Back
CLOSEDQUORUM: Windows malware asks four AI models to pick its next move
SiTech AI Team2 წთ. საკითხავი

CLOSEDQUORUM: Windows malware asks four AI models to pick its next move

Cisco Talos has documented CLOSEDQUORUM, a new Windows malware family that queries four large language models so they autonomously choose its next action on an infected machine.

Cisco Talos researchers have documented a new Windows malware family called CLOSEDQUORUM that queries up to four large language models - Google Gemini, DeepSeek, Qwen and Mistral - and lets them choose its next move once a machine is infected. The vendor's threat intelligence team describes it as the first publicly documented Windows implant to use this approach for command-and-control (C2).

How the quorum decides

The binary is written in Go and no longer waits for instructions from a human operator after deployment. It sends its state to the four models in sequence, tallies their independent verdicts and acts on the result. If the vote is tied, DeepSeek's answer takes precedence, followed by Qwen, Mistral and Gemini.

"The session is closed; no humans are admitted," Talos analyst Ryan Fetterman wrote in a Tuesday blog post. The system prompt extracted from the binary tells each model it is "an advanced malware strategist" and orders it to choose "ONLY executable decisions" from a predefined list.

Steal, inject, persist

The models pick from three capability modules. Steal runs several collection routines at once: it dumps LSASS memory for Windows credentials, lifts saved passwords from Google Chrome, Microsoft Edge and Mozilla Firefox, and extracts cryptocurrency wallet data, including MetaMask, Exodus and Ethereum. Inject generates shellcode and runs it through process hollowing or Early Bird injection, while Persist establishes persistence on the infected device.

Each operator reportedly receives a custom executable with their own Discord webhook and LLM API keys injected at compile time. Stolen credentials are delivered to the operator's Discord channel, encrypted with AES-256-GCM under a daily rotating key derived from the message timestamp.

No attacks seen in the wild

Talos has not observed CLOSEDQUORUM in the wild, but artifacts in the binary link its developer to carding-related posts on criminal forums dating back to 2025. The sample was found with CAIRN, a new toolkit for hunting and classifying AI-integrated malware that Cisco published as an open source repository on Tuesday.

Fetterman argues the most useful detection strategy is behavioural rather than domain blocking, because legitimate applications may contact DeepSeek, Mistral, Gemini or Discord independently - but far fewer should do so while also reading LSASS memory, injecting into suspended processes or creating WMI persistence.

SSiTech

SiTech — AI-powered web development

We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.